7 ms·
I found a WordPress RCEs with GPT5.6 and $25
- j45 2mo agoI wonder if there could be a crowdfunding to harden Wordpress with the leading models, or some who might have access to something like a Mythos level.
- vavkamil 2mo agoThis one is both awesome and scary. We are living in a black mirror episode, where one well-crafted LLM prompt can get you $500k or the ability to hack into 500M websites :)
- cbg0 2mo agoDon't get all starry-eyed, the people owning those sites also have access to LLMs, so both the hacks and paydays are rare.
- wongarsu 2mo agoThe market will quickly adjust to the point where spending $50 on tokens will on average give you a vulnerability valued at $50. Maybe $100 to account for your edge in having a better prompt and the risk of prison time you take in selling the exploit In fact that may well be true today. OP didn't try to sell it to discover the true price the market is willing to pay. And we all know that "somebody paid $$$ for something similar in the past" is no guarantee that somebody else is willing to pay any significant sum for your thing today. If it was, startups would be a lot easier
- hoppp 2mo agoI don't think OP got $500k , it's only clickbait in the title.
- Philip-J-Fry 2mo agoOne LLM prompt can't get you $500K. Why would someone spend $500k instead of just prompting themselves?
- preetham_rangu 2mo agoNice balance between practicality and ambition. Curious how it holds up with real-world scale.
- ahartmetz 2mo agoThe surprising (and possibly untrue) thing is the high price of canned vulnerabilities. WordPress is known as the remote root shell with a blogging feature.
- gorszon 2mo agoPropably untrue, the only way to know is to do threat intelligence, and inflitrate those telegram groups where these brokers operate, I doubt the writer of the article did that. Maybe he conflated any vulnerability with a 0-day one?
- blauditore 2mo ago...or was just looking for a clickbait title. Surely someone once offered a vulnerability for 500k somewhere, but that doesn't mean someone bought it.
- lyu07282 2mo agosome statistics point to almost 50% of all websites on the internet running on Wordpress, $500k for an undisclosed 0day unauthenticated RCE doesn't seem so unrealistic to me
- addedlovely 2mo agoI've got it at 38.32%. I'm looking at the 'front-door' of the web, active sites, no subdomains, from Crux user experience data. Will be publishing a report on www.theweb.report soon - if you're interested. That's a seed of about 13 million domains - pretty sure WordPress would be dominating the even longer tail. ( Also worth noting it's sooo easy to detect a site is WordPress, it screams it across every signal we gather, where-as some sites are just well made and have limited information leaks ).
- denysvitali 2mo agoI still don't understand why, for a blog, a static page isn't enough - especially since most of the WordPress issues are "solved" by adding caching. I do understand it from an user perspective (it's easier to tell the average user to drag and drop rather than committing to a GitHub repo and letting hugo build the website), but from a security standpoint WordPress is really just waiting for a vulnerability (either in the core or on the thousands of plugins) in order to unlock its RCE-as-a-service functionality.
- IshKebab 2mo agoPresumably they don't pay $500k anymore...
- aussieguy1234 2mo agoSo they spent the $25. But the real question here is did they get the $500K?
- elmer2 2mo agoProbably not. The Wordpress Bug Bounty program pays very little. Exploit brokers will pay 500K, but we wouldn't be seeing it here if it was sold.
- az226 2mo agoUnquestionably they did not. Their listed pricing was up to $50k. https://cyber-peace.org/wp-content/uploads/2017/09/ZERODIUM-How-to-Sell-Your-0day-Exploit-to-ZERODIUM.pdf https://cyber-peace.org/wp-content/uploads/2017/09/ZERODIUM-... And that was before LLMs could produce these at volume. The demand (dollars) does not go up commensurately with the supply. So today maybe $500 or a few thousand. Maybe not even that.
- yellow_lead 2mo agoCan RCEs like this still be sold to exploit brokers like Zerodium? If so, how? Asking for a friend
- titularcomment 2mo agolol. Simple case of if you have to ask, you probably shouldn't.
- rvz 2mo agoJust like that, the 0-day black market is experiencing a mini black Monday.
- raesene9 2mo agoInteresting write-up and I do think LLM assisted/powered exploit disclosure is a real concern (I've been able to get models to create container breakouts from Linux LPEs relatively quickly). One thing I'm surprised about is that GPT-5.6 didn't block that prompt due to guardrails. My experience is that GPT-5.5 and up does not like offensive security work (similar to Opus 4.7+/Fable). I didn't notice it but I'd assume that the authors have some level of cyber approvals from OpenAI to relax the guardrails a bit.
- Santas 2mo agoThis might help https://chatgpt.com/cyber https://chatgpt.com/cyber ease the guardrails a bit.
- eru 2mo agoThanks! I wonder if Claude has something similar?
- NiekvdMaas 2mo agoThey do: https://portal.anthropic.com/programs/cvp https://portal.anthropic.com/programs/cvp
- danslo 2mo agoThough this program does not apply to Fable. Which is why most security researchers have started flocking to Sol.
- progbits 2mo agohttps://github.com/WordPress/WordPress/commit/3a640e1c5e39aa60d98bd5a048b603402e70209c https://github.com/WordPress/WordPress/commit/3a640e1c5e39aa... String concatenation SQL injection in the year 2026.
- 9dev 2mo agoThe WordPress codebase is a disgrace. PHP is a beautiful language by now, but they absolutely butcher it and refuse to do anything about that.
- geek_at 2mo agoit would help if they used strict types and modern standards but as you say the wordpress codebase is beyond dated and held together with duckt tape
- asimovDev 2mo agoAs a junior I am glad I happened to start working with PHP on version 7. I had some peeks at our legacy PHP5 stuff (all killed now thankfully) and it looked very different. I am sure it would suck to work with.
- thejosh 2mo agophp7 was such a great time period for PHP, honestly lots of great experimental projects around that time too (HHVM before that, etc).
- mschuster91 2mo agoPHP 8 is good too. Lots of syntactic sugar to make your life so, so much easier.
- khalic 2mo agoI remember multiple projects giving up on rewriting it. Maybe a machine with endless patience could do it?
- throw8394498383 2mo ago[flagged]
- illliillll 2mo agoJust do the KYC and it happily shits out 0days
- ifdefdebug 2mo ago> Is GPT5.6 Sol Superhuman? This is not a simple y/n question. Computers have been superhuman at playing chess for decades now. Reading this article, I guess they are superhuman at understanding code now as well.
- chrisjj 2mo ago> Computers have been superhuman at playing chess for decades now. And at doing arithmetic for even longer /i
- CodeCompost 2mo agoI like the idea of not crediting the person who posted the bug but to the LLM that found it. People who find exploits using LLMs should never get a reward or credit.
- pelagicAustral 2mo agoSo people coding with LLMs shouldn't get paid then, right?
- grey-area 2mo agoThat is in fact the end goal of CEOs pushing LLM use yes. Not possible right now, but if it were they would absolutely take that option.
- bakugo 2mo agoCorrect.
- chrisjj 2mo agoThey should get paid by the LMM only.
- muldvarp 2mo agoDo you assume that five years from now you'll get paid for coding with LLMs?
- jorisw 2mo agoRCE — Remote code execution
- sashank_1509 2mo agoThanks
- cromka 2mo agoThis assumes those who'd pay $500k don't have the skill to use GTP5.6 for the same purpose themselves?
- cheschire 2mo agoYou read articles regularly about how X authority is provided cloud LLM history and uses it as evidence to prosecute a defendant. Yet you think professional criminals are too stupid to launder their activities through an unscrupulous yet legal intermediary?
- khurs 2mo agoPeople who make the money are not necessarily the people who can write the best code. Elon Musk didn't write code for a rocket, he hired people who could.
- elmer2 2mo agoThen why didn't we see the same writeup earlier? If you look through the writeup, you still need the skills to go through what the LLM gives you and actually create a valid proof of concept. I've been using LLMs to find security vulnerabilities and there is no way I can just submit what I found and call it a day (many try).
- mixtureoftakes 2mo agoWhat was the harness used? And yeah surprised about such prompts not being downright blocked, even with the cybersafety verification"
- _superposition_ 2mo agoThe cost of business nowadays? At what point does it become apparent that in today's world software needs continuous pen testing and scanning? If you don't your attackers will.
- alienbaby 2mo ago| in today's world software needs continuous pen testing and scanning points to a bigger problem perhaps; software design, construction and distribution is fundamentally flawed.
- lexicality 2mo agoThe author lost me at the last bit where they started using weird names for the posts. Why would you make one ID O and the other ID 0? Why single letters and not EMBED_01? Why seemingly random letters instead of ABCDEF? Does OCPDST stand for something?
- moebrowne 2mo agoThey are placeholders, their meanings are spelled out in the post: O: publish/oembed_cache, empty content, stale timestamp with parent C C: future/customize_changeset, changeset JSON with parent C P: draft/page, with parent D D: parse/request with itself as its parent S: publish/post, for providing embed data T: publish/post, containing the outer embed
- lexicality 2mo agoThat doesn't actually answer any of my questions though. Why is `S` the placeholder for "post"? T for T'outer?
- stared 2mo agoOn another note - who needs WordPress in the age of Astro and LLMs? I mean, it's not a taunt, but a serious question - do people keep WordPress because it used to be the easiest solution to set up years ago, or are there still clear use cases where one can argue it's the best solution?
- crummy 2mo agodoes Astro do WYSWIYG?
- justanotherunit 2mo agoI have not yet seen an alternative for Wordpress + woocommerce for a simple e-commerce site that is not more expensive. I am open for alternatives tho if anyone knows any
- cadamsdotcom 2mo agoThat was an incredible writeup! Chapeau to the author - thanks for taking the time to do a writeup. When Anthropic claimed Mythos chained 4 or 5 bugs to achieve sandbox escape and found bugs in core software, it sounded like bs. But here we are 2 months later seeing what they meant. Cybersecurity was always a hard sell; security flaws were invisible - by contrast a fence with a hole is visible to everyone - anyone can ignore the locked gate and walk through the fence hole. With cybersecurity a hole in the fence may go unnoticed for years, maybe forever. LLMs level the field. We will all benefit from more secure systems, a few people will get a lot of egg on their faces, and it will end the malpractice of underinvesting in software security to get a product out the door.
- dzonga 2mo agowordpress is so shitty - though it runs the majority of the web. people think PHP is shitty cz of Wordpress. at a certain point in time - people need to move to better ecosystems painful as that may be.
- f311a 2mo agoHistorically, a lot vulnerabilities in PHP projects were because of PHP itself. Things like register_globals, remote includes/reads using functions that supposed to read local data and so on.
- Zsfe510asG 2mo agoThere is no evidence that $500k has been paid or would be paid for an exploit like this one. Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k. The author works for https://www.assetnote.io/ https://www.assetnote.io/ , which has AI products for automated scanning.
- functionmouse 2mo ago[flagged]
- kuroguro 2mo agoLikely referencing https://www.crowdfense.com/exploit-acquisition-program/ https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zerodium_WordPress_exploit.png https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full payment or not for something similar.
- lillesvin 2mo agoI feel like I've seen plenty of non-AI, pre-2020 SAST tools catch SQLis like the one mentioned here, and if nothing else, then a code review ought to catch it. Is WordPress not using code reviews and/or SAST?
- f311a 2mo agoThey would not catch it, it requires combining multiple vulns.
- hmokiguess 2mo agoI am so done with FOMO writing. Sure man, you found one with $25. With $25 plus your entire industry domain specific knowledge of where to look, of how to probe, of what else you may have accumulated and collected over the years of working within this industry. Let's stop with the gambling narrative and the illusion that we are all missing out.
- w4yai 2mo agoI agree. This is so toxic! It feels like the Instagram of articles. "Look how my life is great" - yeah sure, you're posting only happy moments. Not only $25 is not accounting the years of experience, but also all the failed attempts.
- assanineass 2mo ago[dead]
- recitedropper 2mo agoI can't agree with this more. May cooler, more compassionate minds prevail.
- deaton 2mo agoAnd nobody would post "I did it for free!" if they had done it themselves, but somehow spending $25 on tokens changes how we're supposed to look at it
- paodealho 2mo agoShould also note the math done on the token costs. $25 of subsidized tokens because he's on a subscription plan.
- r1ch 2mo agoDoes Sol allow this kind of research by default or is this a "look at me I'm on the cyber research allowlist" post?
- deleted 2mo ago[deleted]
- tantalor 2mo agoIs this real? Or did they concoct this vulnerability just to write a blog post? I'm not seeing any mention where they report this to WP or the patch.
- testplzignore 2mo agohttps://github.com/WordPress/WordPress/commit/c474dc6051dd6067f097cf7368c42d73a81621ee https://github.com/WordPress/WordPress/commit/c474dc6051dd60...
- perarneng 2mo agoHow do you find exploits without risking someone seeing your attempt and reporting you as a hacker? do you register first somewhere?
- kamranjon 2mo agoYou can run Wordpress locally in your own sandbox to test these vulnerabilities, you don’t have to break any laws.
- supportm 2mo ago[flagged]
- _joel 2mo agoThe "pro's buy out a company that has a massive add-on install base with the most non-technical users.
- koko443 2mo ago[dead]
- secretslol 2mo agoOne of my websites was hacked with this, luckily not one with any users at all. They did this: - Two admin accounts in the database. - plugin dir: wp-content/plugins/wp-core with remote command-execution web shell wp-core-[12 random chars].php - firewall.php backdoor in mu-plugins dir with admin on GET ?sergei - cache-seo-helper.php backdoor - fixer.php which renames the wordpress version number to one which is patched. I have decided to give up on Wordpress.
- throwitaway222 2mo agoSeems like exploit brokers can just buy a codex license and put the 500k towards finding all bugs in all software for the price of one bug
- barbazoo 2mo agoI'd expect the amount of money paid for exploits to go down then. It's inefficient to pay >$25 for an exploit that took $25 to make.
- ameliaquining 2mo agoI might be missing something, so perhaps someone can explain: Why are the steps in the middle of the exploit chain necessary? The writeup describes getting a SQL injection, then going from there to cache poisoning to exploiting various logic bugs, to eventually creating an admin account (and WordPress grants RCE to admin accounts by design). But if you have a SQL injection, why can't you use that to just create an admin account directly, by inserting it into the users table?
- mariushh 2mo ago[dead]